{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:17:56Z","timestamp":1784391476102,"version":"3.55.0"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031280726","type":"print"},{"value":"9783031280733","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-28073-3_5","type":"book-chapter","created":{"date-parts":[[2023,3,1]],"date-time":"2023-03-01T06:04:47Z","timestamp":1677650687000},"page":"59-78","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["A Review of\u00a0Intrusion Detection Systems Using Machine Learning: Attacks, Algorithms and\u00a0Challenges"],"prefix":"10.1007","author":[{"given":"Jose Luis","family":"Gutierrez-Garcia","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Eddy","family":"Sanchez-DelaCruz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maria del Pilar","family":"Pozos-Parra","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,3,2]]},"reference":[{"key":"5_CR1","unstructured":"Bettina, J., Baudilio, M., Daniel, M., Alajandro, B., Michiel, S.: Challenges to effective EU cybersecurity policy. European Court of Auditors, pp. 1\u201374 (2019)"},{"key":"5_CR2","unstructured":"Gerling, R.: Cyber Attacks on Free Elections. MaxPlanckResearch, pp. 10\u201315 (2017)"},{"key":"5_CR3","unstructured":"World Economic Forum. The Global Risks Report 2020. Insight Report, pp. 1\u2013114 (2020). 978-1-944835-15-6. http:\/\/wef.ch\/risks2019"},{"key":"5_CR4","unstructured":"Ponemon Institute. 2015 Cost of Data Breach Study: Impact of Business Continuity Management (2018). https:\/\/www.ibm.com\/downloads\/cas\/AEJYBPWA"},{"key":"5_CR5","unstructured":"Katsumi, N.: Global Threat Intelligence Report Note from our CEO. NTT Security (2019)"},{"key":"5_CR6","volume-title":"Machine Learning and Security","author":"C Chi","year":"2018","unstructured":"Chi, C., Freeman, D.: Machine Learning and Security. O\u2019Reilly, Sebastopol (2018)"},{"key":"5_CR7","unstructured":"Kapersky. Project TajMahal a new sophisticated APT framework. Kapersky (2019). https:\/\/securelist.com\/project-tajmahal\/90240\/"},{"key":"5_CR8","unstructured":"CyberEdge Group. Cyberthreat Defense Report. CyberEdge Group (2019). https:\/\/cyber-edge.com\/"},{"key":"5_CR9","unstructured":"Hanan, H., et al.: A Taxonomy and Survey of Intrusion Detection System Design Techniques, Network Threats and Datasets. ACM (2018). http:\/\/arxiv.org\/abs\/1806.03517"},{"key":"5_CR10","doi-asserted-by":"publisher","unstructured":"Mazel, J., Casas, P., Fontugne, R., Fukuda, K., Owezarski, P.: Hunting attacks in the dark: clustering and correlation analysis for unsupervised anomaly detection. Int. J. Netw. Manag. 283\u2013305 (2015). https:\/\/doi.org\/10.1002\/nem.1903","DOI":"10.1002\/nem.1903"},{"issue":"1","key":"5_CR11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s42400-019-0038-7","volume":"2","author":"A Khraisat","year":"2019","unstructured":"Khraisat, A., Gondal, I., Vamplew, P., Kamruzzaman, J.: Survey of intrusion detection systems: techniques, datasets and challenges. Cybersecurity 2(1), 1\u201322 (2019). https:\/\/doi.org\/10.1186\/s42400-019-0038-7","journal-title":"Cybersecurity"},{"key":"5_CR12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-02354-5","volume-title":"Anomaly Detection as a Service: Challenges, Advances, and Opportunities","author":"D Yao","year":"2018","unstructured":"Yao, D., Shu, X., Cheng, L., Stolfo, S.: Anomaly Detection as a Service: Challenges, Advances, and Opportunities. Morgan & Claypool Publishers, San Rafael (2018)"},{"key":"5_CR13","unstructured":"KDD. KDD-CUP-99 Task Description (1999). https:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/ task.html"},{"key":"5_CR14","doi-asserted-by":"publisher","unstructured":"Sharafaldin, I., Habibi, A., Ghorbani, A.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: ICISSP 2018 - Proceedings of the 4th International Conference on Information Systems Security and Privacy, pp. 108\u2013116 (2018). https:\/\/doi.org\/10.5220\/0006639801080116","DOI":"10.5220\/0006639801080116"},{"key":"5_CR15","doi-asserted-by":"publisher","unstructured":"Ring, M., Wunderlich, S., Scheuring, D., Landes, D., Hotho, A.: A survey of network-based intrusion detection data sets. Comput. Secur. 147\u2013167 (2019). https:\/\/arxiv.org\/abs\/1902.00053. https:\/\/doi.org\/10.1016\/j.cose.2019.06.005","DOI":"10.1016\/j.cose.2019.06.005"},{"issue":"11","key":"5_CR16","doi-asserted-by":"publisher","first-page":"2375","DOI":"10.3390\/app9112375","volume":"9","author":"R Ullah","year":"2019","unstructured":"Ullah, R., Zhang, X., Kumar, R., Amiri, N., Alazab, M.: An adaptive multi-layer botnet detection technique using machine learning classifiers. Appl. Sci. 9(11), 2375 (2019)","journal-title":"Appl. Sci."},{"key":"5_CR17","doi-asserted-by":"publisher","DOI":"10.3390\/app10051775","author":"R Mag\u00e1n-Carri\u00f3n","year":"2020","unstructured":"Mag\u00e1n-Carri\u00f3n, R., Urda, D., D\u00edaz-Cano, I., Dorronsoro, B.: Towards a reliable comparison and evaluation of network intrusion detection systems based on machine learning. Appl. Sci. (2020). https:\/\/doi.org\/10.3390\/app10051775","journal-title":"Appl. Sci."},{"key":"5_CR18","doi-asserted-by":"publisher","unstructured":"Qiu, S., Liu, Q., Zhou, S., Wu, C.: Review of artificial intelligence adversarial attack and defense technologies. Appl. Sci. (2019). https:\/\/doi.org\/10.3390\/app9050909","DOI":"10.3390\/app9050909"},{"key":"5_CR19","unstructured":"Carlini, N., et al.: On Evaluating Adversarial Robustness (2019). https:\/\/arxiv.org\/abs\/1902.06705"},{"key":"5_CR20","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1016\/j.jss.2019.01.051","volume":"151","author":"F Ullaha","year":"2019","unstructured":"Ullaha, F., Babara, M.: Architectural tactics for big data cybersecurity analytics systems: a review. J. Syst. Softw. 151, 81\u2013118 (2019). https:\/\/doi.org\/10.1016\/j.jss.2019.01.051","journal-title":"J. Syst. Softw."},{"key":"5_CR21","doi-asserted-by":"publisher","first-page":"710","DOI":"10.1016\/j.future.2019.06.026","volume":"102","author":"D Chadwick","year":"2020","unstructured":"Chadwick, D., et al.: A cloud-edge based data security architecture for sharing and analysing cyber threat information. Future Gener. Comput. Syst. 102, 710\u2013722 (2020). https:\/\/doi.org\/10.1016\/j.future.2019.06.026","journal-title":"Future Gener. Comput. Syst."},{"key":"5_CR22","unstructured":"Menen, A., Gowtham, R.: An efficient ransomware detection system. Int. J. Recent Technol. Eng. 28\u201331 (2019)"},{"key":"5_CR23","unstructured":"Narayanan, S., Ganesan, S., Joshi, K., Oates, T., Joshi, A., Finin, T.: Cognitive Techniques for Early Detection of Cybersecurity Events (2018). http:\/\/arxiv.org\/abs\/1808.00116"},{"key":"5_CR24","doi-asserted-by":"publisher","unstructured":"Ravi, S., Jassi, J., Avdhesh, S., Sharma, R.: Data-mining a mechanism against cyber threats: a review. In: 2016 1st International Conference on Innovation and Challenges in Cyber Security, ICICCS 2016, pp. 45\u201348 (2016). https:\/\/doi.org\/10.1109\/ICICCS.2016.7542343","DOI":"10.1109\/ICICCS.2016.7542343"},{"key":"5_CR25","unstructured":"Daya, A., Salahuddin, M., Limam, N., Boutaba, R.: A graph-based machine learning approach for bot detection. In: 2019 IFIP\/IEEE Symposium on Integrated Network and Service Management, IM 2019, pp. 144\u2013152 (2019)"},{"issue":"11","key":"5_CR26","doi-asserted-by":"publisher","first-page":"2375","DOI":"10.3390\/app9112375","volume":"9","author":"R Ullah","year":"2019","unstructured":"Ullah, R., Zhang, X., Kumar, R., Amiri, N., Alazab, M.: An adaptive multi-layer botnet detection technique using machine learning classifiers. Appl. Sci. 9(11), 2375 (2019). https:\/\/doi.org\/10.3390\/app9112375","journal-title":"Appl. Sci."},{"issue":"7","key":"5_CR27","doi-asserted-by":"publisher","first-page":"1392","DOI":"10.3390\/app9071392","volume":"9","author":"T Le","year":"2019","unstructured":"Le, T., Kim, Y., Kim, H.: Network intrusion detection based on novel feature selection model and various recurrent neural networks. Appl. Sci. 9(7), 1392 (2019). https:\/\/doi.org\/10.3390\/app9071392","journal-title":"Appl. Sci."},{"key":"5_CR28","unstructured":"Zhou, Q.: Dimitrios Pezaros School. Evaluation of Machine Learning Classifiers for Zero-Day Intrusion Detection - An Analysis on CIC-AWS-2018 dataset (2019). https:\/\/arxiv.org\/abs\/1905.03685"},{"issue":"1","key":"5_CR29","doi-asserted-by":"publisher","first-page":"173","DOI":"10.3390\/electronics9010173","volume":"9","author":"A Khraisat","year":"2020","unstructured":"Khraisat, A., Gondal, I., Vamplew, P., Kamruzzaman, J., Alazab, A.: Hybrid intrusion detection system based on the stacking ensemble of C5 decision tree classifier and one class support vector machine. Electronics 9(1), 173 (2020). https:\/\/doi.org\/10.3390\/electronics9010173","journal-title":"Electronics"},{"issue":"3","key":"5_CR30","doi-asserted-by":"publisher","first-page":"1065","DOI":"10.3390\/app10031065","volume":"10","author":"W Liu","year":"2020","unstructured":"Liu, W., Ci, L., Liu, L.: A new method of fuzzy support vector machine algorithm for intrusion detection. Appl. Sci. 10(3), 1065 (2020). https:\/\/doi.org\/10.3390\/app10031065","journal-title":"Appl. Sci."},{"key":"5_CR31","doi-asserted-by":"publisher","unstructured":"Gao, M., Ma, L., Liu, H., Zhang, Z., Ning, Z., Xu, J.: Malicious network traffic detection based on deep neural networks and association analysis. Sensors 20, 1\u201314 (2020). https:\/\/doi.org\/10.3390\/s20051452","DOI":"10.3390\/s20051452"},{"issue":"3","key":"5_CR32","doi-asserted-by":"publisher","first-page":"794","DOI":"10.3390\/app10030794","volume":"10","author":"D Gonzalez-Cuautle","year":"2020","unstructured":"Gonzalez-Cuautle, D., et al.: Synthetic minority oversampling technique for optimizing classification tasks in botnet and intrusion-detection-system datasets. Appl. Sci. 10(3), 794 (2020). https:\/\/doi.org\/10.3390\/app10030794","journal-title":"Appl. Sci."},{"key":"5_CR33","doi-asserted-by":"publisher","first-page":"1","DOI":"10.3390\/sym12020203","volume":"12","author":"M Sarnovsky","year":"2020","unstructured":"Sarnovsky, M., Paralic, J.: Hierarchical intrusion detection using machine learning and knowledge model. Symmetry 12, 1\u201314 (2020)","journal-title":"Symmetry"},{"key":"5_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cose.2019.101645","volume":"88","author":"M Wang","year":"2020","unstructured":"Wang, M., Lu, Y., Qin, J.: A dynamic MLP-based DDoS attack detection method using feature selection and feedback. Comput. Secur. 88, 1\u201314 (2020). https:\/\/doi.org\/10.1016\/j.cose.2019.101645","journal-title":"Comput. Secur."},{"issue":"1","key":"5_CR35","doi-asserted-by":"publisher","first-page":"7","DOI":"10.3390\/sym12010007","volume":"12","author":"S Kumar","year":"2019","unstructured":"Kumar, S., Rahman, M.: Effects of machine learning approach in flow-based anomaly detection on software-defined networking. Symmetry 12(1), 7 (2019)","journal-title":"Symmetry"},{"issue":"16","key":"5_CR36","doi-asserted-by":"publisher","first-page":"3414","DOI":"10.3390\/app9163414","volume":"9","author":"R Hwang","year":"2019","unstructured":"Hwang, R., Peng, M., Nguyen, V., Chang, Y.: An LSTM-based deep learning approach for classifying malicious traffic at the packet level. Appl. Sci. 9(16), 3414 (2019). https:\/\/doi.org\/10.3390\/app9163414","journal-title":"Appl. Sci."},{"issue":"12","key":"5_CR37","doi-asserted-by":"publisher","first-page":"738","DOI":"10.3390\/sym10120738","volume":"10","author":"H Kwon","year":"2018","unstructured":"Kwon, H., Kim, Y., Yoon, H., Choi, D.: Random untargeted adversarial example on Deep neural network. Symmetry 10(12), 738 (2018). https:\/\/doi.org\/10.3390\/sym10120738","journal-title":"Symmetry"},{"key":"5_CR38","doi-asserted-by":"publisher","unstructured":"Anirban, C., Manaar, A., Vishal, D., Anupam, C., Debdeep, M.: Adversarial attacks and defences: a survey. IEEE Access 35365\u201335381 (2018). https:\/\/doi.org\/10.1109\/ACCESS.2018.2836950","DOI":"10.1109\/ACCESS.2018.2836950"},{"key":"5_CR39","unstructured":"Ibitoye, O., Abou-Khamis, R., Matrawy, A., Shafi, M.: The Threat of Adversarial Attacks on Machine Learning in Network Security - A Survey (2019). https:\/\/arxiv.org\/abs\/1911.02621"},{"key":"5_CR40","unstructured":"Niyaz, Q., Sun, W., Javaid, A., Alam, M.: A deep learning approach for network intrusion detection system. In: 9th EAI International Conference on Bio-Inspired Information and Communications Technologies, pp. 1\u201311, May 2016"},{"key":"5_CR41","doi-asserted-by":"crossref","unstructured":"Guo, W., Mu, D., Xu, J., Su, P., Wang, G., Xing, X.: Lemna: explaining deep learning based security applications. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada, 15 October 2018, pp. 364\u2013379 (2018)","DOI":"10.1145\/3243734.3243792"},{"key":"5_CR42","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/TETCI.2017.2772792","volume":"2","author":"S Nathan","year":"2018","unstructured":"Nathan, S., Tran, N., Vu, P., Qi, S.: A deep learning approach to network intrusion detection. IEEE Trans. Emerg. Top. Comput. Intell. 2, 41\u201350 (2018). https:\/\/doi.org\/10.1109\/TETCI.2017.2772792","journal-title":"IEEE Trans. Emerg. Top. Comput. Intell."},{"issue":"1","key":"5_CR43","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/1804\/1\/012136","volume":"1804","author":"SA Abbas","year":"2021","unstructured":"Abbas, S.A., Almhanna, M.S.: Distributed denial of service attacks detection system by machine learning based on dimensionality reduction. J. Phys. Conf. Ser. 1804(1), 012136 (2021). https:\/\/doi.org\/10.1088\/1742-6596\/1804\/1\/012136","journal-title":"J. Phys. Conf. Ser."},{"key":"5_CR44","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.108076","volume":"192","author":"N Gupta","year":"2021","unstructured":"Gupta, N., Jindal, V., Bedi, P.: LIO-IDS: handling class imbalance using LSTM and improved one-vs-one technique in intrusion detection system. Comput. Netw. 192, 108076 (2021). https:\/\/doi.org\/10.1016\/j.comnet.2021.108076","journal-title":"Comput. Netw."},{"key":"5_CR45","doi-asserted-by":"crossref","unstructured":"Liu, X., Li, T., Zhang, R., Wu, D., Liu, Y., Yang, Z.: A GAN and Feature Selection-Based Oversampling Technique for Intrusion Detection (2021)","DOI":"10.1155\/2021\/9947059"},{"key":"5_CR46","doi-asserted-by":"publisher","first-page":"22351","DOI":"10.1109\/access.2021.3056614","volume":"9","author":"ZK Maseer","year":"2021","unstructured":"Maseer, Z.K., Yusof, R., Bahaman, N., Mostafa, S.A., Foozy, C.F.M.: Benchmarking of machine learning for anomaly based intrusion detection systems in the CICIDS2017 dataset. IEEE Access 9, 22351\u201322370 (2021). https:\/\/doi.org\/10.1109\/access.2021.3056614","journal-title":"IEEE Access"}],"container-title":["Lecture Notes in Networks and Systems","Advances in Information and Communication"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-28073-3_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,3,1]],"date-time":"2023-03-01T06:05:23Z","timestamp":1677650723000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-28073-3_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031280726","9783031280733"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-28073-3_5","relation":{},"ISSN":["2367-3370","2367-3389"],"issn-type":[{"value":"2367-3370","type":"print"},{"value":"2367-3389","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"2 March 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"FICC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Future of Information and Communication Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"San Francisco, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 March 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 March 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ficc2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}